Data is a fundamental element in all digital innovation processes. Virtually every activity generates an ever-increasing quantity of data, which all too often goes unused or is incorrectly utilised by some economic actors. News reports frequently inform us of data privacy violations in the European Economic Area, most notably those involving GDPR compliance, which, since 2016, has been the forerunner for several related EU initiatives. More recently, we have witnessedthe approval of the Data Governance Act and the Data Act,otherwise known as the European Data Law..
In this article, we will examine the implications of the Data Act for both the public and private sectors, for businesses and for private individuals, from 12 September 2025, the date on which it will come fully into force.
An essential point should be made in advance. Beyond its value as a legal instrument, the Data Act is a true framework that companies will have to adopt to allow access to their data in the situations outlined in the EU regulation..
It is therefore crucial to be prepared on two fronts: ensuring compliance with the regulation and avoiding unnecessary risks to company data.
What is the Data Act
The Data Act can be accurately translated, in terms of its full meaning, as Data Law. It is a regulation devised by the European legislator to support the EU’s data economy.There are two main objectives: to protect the competitiveness of businesses and the common right to have more accessible and usable data, while also encouraging activity in the public sector..
At least on paper, the Data Act aims to clarify who can use certain data and, above all, under what conditions, so as to avoid penalties.
In many sections, it is clear that the law aims to safeguard competition in the European cloud market, with measures intended to protect SMEs from the technological and contractual power exercised by big tech companies.
Recent sanctions imposed on Google (antitrust), Meta (GDPR violations), and Apple (DMA violation and tax avoidance) confirm this intent on the part of the European authorities, after years in which Silicon Valley giants have thrived by exploiting grey areas in the regulations.
A notable innovation in the Data Act is the possibility for public bodies to request data from private entities, where there is an exceptional public interest, according to a set of rules that should protect all parties without discouraging entrepreneurial activity.
Additional safeguards ensure regulation of activity within the European Economic Area and prevent non-EU countries (the US, in particular) from accessing data under conditions that contravene EU rules.
The Data Act complements the scope of the Data Governance Act, applicable since September 2023, seeking to provide concrete answers on the legal frameworks that will regulate access to and use of data in the European Economic Area.
Data Act Regulation
The Data Act regulation comprises nine chapters, starting with general provisions, followed by:
- Chapter II: Data sharing between businesses and consumers in the context of IoT.
- Chapter III: data sharing between businesses, in cases where this is required by European law.
- Chapter IV: limiting abusive contractual clauses to protect businesses, with particular attention to SMEs.
- Chapter V: data sharing between businesses and public administrations, including cases where public authorities may access certain private sector data.
- Chapter VI: switching between data processing services, with a focus on interoperability criteria that cloud and edge providers must guarantee.
- Chapter VII: unlawful government access by third countries, to prevent indiscriminate access to non-personal data pertaining to activities under EU jurisdiction.
- Chapter VIII: data interoperability, especially regarding cloud services.
- Chapter IX: enforcement of the Data Act, with the designation of a responsible body by each EU Member State.
The Origins of the Data Act
The initial step towards what eventually became the Data Act dates back to 23 February 2022, with the European Commission’s proposal.
From its first draft, the regulation impacted Directive 96/9/EC of the European Parliament and Council (11 March 1996), which governed the legal protection of databases.
Following a legislative process marked by debates among member states, the Council and European Parliament reached a provisional agreement on the final version of the Data Act on 27 June 2023.
The proposal was further refined and officially adopted by the Council on 27 November 2023, and published in the Official Journal of the European Union on 22 December 2023.
The Data Act’s grace period will end on 12 September 2025, by which time all relevant parties must comply with the regulation’s provisions, which are directly applicable without the need for transposition into national law, unlike EU directives.
How does the Data Act work
According to the European Commission’s guidance notes, the Data Act is a framework that: “Provides an alternative model to the data management practices of Big Tech platforms, which have acquired significant market power by controlling large quantities of data. In practice, data intermediaries should act as neutral third parties connecting individuals and businesses with data users. […] There must be a structural separation between the data intermediation service and any other services provided (i.e., they must be legally distinct)”.
Put more simply, the Data Act stipulates that data generated through a digital service in the first instance belongs to the user.This perspective upends the notion that allowed big tech to thrive by exploiting indiscriminately user-generated content.
Thanks to the Data Act, users have the right to request and obtain a copy of all the data that a company has collected from them through its services. Users can therefore access the information that the provider has gathered, such as purchasing habits, browsing preferences, and websites visited.
The Data Act also introduces the principle of data portability, which allows, at least in principle, for data to be transferred easily from one service to another. A common example is the desire to change cloud service provider. In this situation, the user must be able to transfer their data without having to recreate it from scratch.
Another major innovation is the obligation for companies to share data with third parties, such as public authorities, when necessary for the pursuit of public interest, as defined by law.
The main stakeholders in the data landscape are users, businesses, service providers, and the European Union:
- Users: with the Data Act, they can exercise greater control over their own data and regain possession with far greater ease than before.
- Companies: particularly manufacturers of connected products (smartphones, smart appliances, and other IoT systems) must comply with the new rules by guaranteeing users both access to data and data portability.
- Service providers (cloud providers): cloud service providers and other online service providers will also have to comply with the new rules, allowing users to transfer their data without deliberately creating lock-in situations.
- The European Union:through the Data Act, the EU sets the rules, guaranteeing a clear and consistent regulatory environment across the European Economic Area. The aim is to create a single data market, boosting innovation and economic growth. The EU must also work with Member States to ensure the regulation is properly implemented nationally.
Data Act for businesses
The Data Act regulates various aspects of data processing within the european economic area, extending a series of regulations that began with the GDPR almost ten years ago. It is not revolutionary, but rather a necessary step to bring order to a complex and fragmented landscape.
Scope of application
The Data Act will apply to both personal and non-personal data, including metadata, processed in all economic sectors, both public and private. It will cover all connected products placed on the European market.
In cases of overlap, the CE has already clarified that the provisions of the GDPR take precedence, with which companies have been required to comply since 2018.
According to the regulation, there are three parties required to comply with the Data Act: the data subject, the data holder, and the data recipient, as defined in various paragraphs of Article 2:
-
-
- The data subject, that is, the natural person to whom the personal data refer, as specified in Article 4 of the GDPR, as well as the user, meaning the natural or legal person who owns a connected product, has been contractually granted temporary rights to use such a connected product, or receives a related service;
- The data holder, that is, the entity with a legal right to the data and the obligation to make available the data generated and/or collected by the connected product, or in the course of providing a related service, to the user or to a third party designated by the user;
- The data recipient, that is, a natural or legal person acting for purposes related to their business, other than the user of a connected product, who receives data from the data holder and may therefore be a third party designated following a request by the user to the data holder.
-
Obligations and implications
Articles 3 and 4 of the Data Act set out the obligations to which data holders are subject, in order to make product and related service data accessible to the user: "including the metadata necessary to interpret such data, by making them available to the user, and consequently granting the user the right to access and use the generated data easily, securely, free of charge, in a complete, structured, commonly used, and machine-readable format."”.
With regard to data processing, the Data Act is consistent with the GDPR and the Data Governance Act. Additional provisions are introduced concerning data access between multiple private enterprises.
Data holders must ensure data protection and adopt appropriate cybersecurity measures, in accordance with regulations such as the GDPR and NIS 2. Specific provisions are provided for highly regulated sectors, such as fintech and medtech, as well as for the regulation of interconnected vehicles.
Companies required to share data may, in accordance with the specified procedures, still exercise the right to object to users’ requests for access and portability.
As previously established, there are no exceptions regarding data sovereignty: data must still be stored and processed within the european economic area.
Greater operational efficiency
If approached correctly, the Data Act takes on a distinctly proactive dimension, encouraging the companies concerned to carry out a series of data-related activities that they should have undertaken in any case.
È infatti necessario uno standard elevato di protezione e sicurezza dei dati, ancor prima di entrare nel merito degli aspetti legati al data sharing, che costituiscono la principale novità di questo regolamento europeo.
It should be noted that the Data Act is not merely a set of requirements to be passively fulfilled in order to avoid the heavy penalties provided for.
The Data Act offers new business opportunities for companies that are able to make the most of data-driven services, especially given the increasingly interconnected direction in which we are heading.
The most forward-thinking companies are those that, since the introduction of the GDPR, have invested in a genuine data strategy rather than simply reacting to each new regulation. This has enabled them to maintain full control over their digital assets.
Staying deliberately high-level, the Data Act suggests useful measures for making existing processes more efficient and for developing new business scenarios based on data connectivity. Numerous services are required to ensure the effective exploitation of these opportunities.
Ensuring more effective data circulation and greater portability, in addition to being an obligation, can in fact represent a new opportunity, both for improving internal processes and for developing new commercial offerings based on services provided to third parties.
Data Act for consumers
In various articles of the Data Act, the intention of the European legislator to protect consumers on several levels is clear. It is necessary to ensure greater transparency and control over data, without neglecting the privacy of both personal and non-personal information. In addition, all measures aimed at facilitating access to and portability of data across different providers must be considered.
Greater transparency and control over data
Unless otherwise provided by law, the data holder cannot deny full transparency regarding the use of the data to the recipients.
Consumers cannot abuse this condition, as service providers, even though they cannot deny access to data, have appropriate means at their disposal to protect their trade secrets and intellectual property.
Improved privacy protection
Privacy Preserving Technologies (PPT) are proving to have a significant impact across various sectors, ensuring the secure management of data without compromising collaboration and innovation.
To eliminate any doubt, the Data Act establishes that non-personal data must be treated in the same way as personal data, subjecting them to the same requirements as those set out in the GDPR.
In this sense, investment in PPT technologies could serve as a practical example of a business opportunity introduced by the Data Act itself, as their widespread adoption can reasonably be expected in the coming years.
The issue of data anonymisation remains as relevant as ever and is far from beingresolvedThis is a condition that is difficult to guarantee in full. There are many AI applications capable of correlating data from various sources to identify previously anonymised users, undermining the privacy provisions established by EU law.
Data access and portability
The Data Act requires providers to allow access to and reuse of data collected through their products and services.
This aspect could significantly change the way services are designed, with all the associated pros and cons. Providers will not be able to hide indefinitely behind the protection of trade secrets, but at the same time, they are not required to open up their assets to third parties without restriction.
This could therefore lead to new standoffs between the EU and big tech companies, each with their own arguments, which may or may not be considered valid depending on one’s perspective.
While we await a clearer understanding of the actual impact of the Data Act, it is reasonable to expect that its provisions will ultimately promote the growth of open data initiatives and encourage the development of new services based on public-private collaboration.
The challenges of the Data Act
The initial reactions to the approval of the Data Act, similar to what is happening with the DMA (Digital Markets Act), suggest that the obligation of openness established by the regulation may especially discourage big tech companies from marketing certain services and products within the European market.
This could undermine a scenario of free competition, depriving European businesses and citizens of a range of exclusive opportunities offered only by non-EU actors, with no viable alternatives available in practice.
The European authorities will need to manage this complex situation with balance, guided by the overarching aim of curbing the excessive power of big tech in the often unrestrained exploitation of user data generated through their services on a global scale.
Compliance complexity
For some companies—especially those in highly regulated sectors or whose business relies on the exclusivity of data processing granted by their clients—achieving full compliance with the Data Act may not be straightforward. It should also be noted that the adoption deadline is quite strict, being set for September 2025.
Various aspects will need to be clarified, such as the potential overlap between the Data Act and the Digital Markets Act. For example, according to the DMA, repair services for a product cannot remain the exclusive domain of the manufacturer, as this would disadvantage the consumer.
At the same time, opening up systems and enabling free data sharing could present genuine challenges from a cybersecurity perspective.
Striking a balance between all the interests at stake is a highly complex goal, particularly for a piece of legislation that must generalise scenarios in order to ensure impartiality in its application.
Implementation costs
Compliance with the Data Act, in ensuring the access and portability of data as required by the regulation, is by no means a trivial issue. In some cases, it may require a complete redesign of the service, with costs and timelines that could make the provision of certain products or services unprofitable for providers. The most obvious countermeasure would be an increase in market prices, which would in turn disadvantage consumers.
Coordination between different jurisdictions
In an increasingly global market, where many of the main producers of data-enabling technologies are based outside the EU, achieving European economic sovereignty is far from guaranteed.
Some companies may reconsider their commercial strategies by limiting the range of products and services distributed in Europe, with negative consequences for competition and innovation.
On the other hand, this situation could encourage investment in European companies. However, some of the most important services in the context of interconnected data require the economic strength and unique technological background of US big tech firms.
Moxoff and the Data Act
The growing legislative framework on data that the European Union aims to promote is now made up of a significant number and variety of instruments. In addition to factors related to data processing, there is the added complexity of cybersecurity(NIS 2)and the impact of emerging technologies(AI Act)Further specific considerations apply to certain markets, such as the financial sector (DORA Regulation).
This evolving scenario should not lead companies to view legislation as a mere formality, a checklist of activities to be ticked off in order to achieve compliance and, with a bit of luck, avoid the heavy penalties involved.
A sufficiently responsible business vision requires the development of a robust data strategy. Such an approach helps generate value from data in any usage context, transforming consumer rights into the ability to meet their needs.
Companies should consider seeking support from a partner with proven experience in data and the technologies needed to maximise their value. This valuable added expertise helps achieve business objectives and respond to the evolving needs of customers.
Whether it concerns new regulatory requirements or sudden changes in market demand, Moxoff ensures reliability and efficiency in developing a robust data strategy. This is achieved through innovative solutions based on advanced models and cutting-edge technologies, supporting sustainable long-term growth.